Using visual motifs to classify encrypted traffic

Using visual motifs to classify encrypted traffic
复制标题

使用视觉主题对加密流量进行分类

DOI:
10.1145/1179576.1179584
复制
发表时间:
2006
期刊:
2008 34th European Conference on Optical Communication
影响因子:
--
通讯作者:
G. Masson
G. Masson
中科院分区:
--
文献类型:
--
作者:
C. V. Wright;F. Monrose;G. Masson

文献摘要

被引文献

相似文献

为了使鲁棒的流量分类更容易被人类操作员使用,我们提出了网络流量的可视化技术。我们的技术完全基于应用层加密后保持完整的网络信息,因此提供了一种“在黑暗中”可视化流量的方法。我们的可视化清楚地说明了常见应用协议之间的差异,包括它们的瞬态(即,依赖于时间的)和稳态行为。我们将展示如何使用这些可视化来帮助操作人员识别未识别流量中的应用程序协议,并通过视觉检查验证自动分类器的结果。特别是,我们的初步结果表明,我们可以在不到一个小时的时间内可视化地扫描近45,000个连接,并正确识别已知的应用程序行为。此外,利用可视化和基于动态时间扭曲的自动比较技术,我们可以快速开发出准确的识别器,用于新的或以前未知的应用。
In an effort to make robust traffic classification more accessible to human operators, we present visualization techniques for network traffic. Our techniques are based solely on network information that remains intact after application-layer encryption, and so offer a way to visualize traffic "in the dark". Our visualizations clearly illustrate the differences between common application protocols, both in their transient (i.e., time-dependent)and steady-state behavior. We show how these visualizations can be used to assist a human operator to recognize application protocols in unidentified traffic and to verify the results of an automated classifier via visual inspection. In particular, our preliminary results show that we can visually scan almost 45,000 connections in less than one hour and correctly identify known application behaviors. Moreover, using visualizations together with an automated comparison technique based on Dynamic Time Warping of the motifs, we can rapidly develop accurate recognizers for new or previously unknown applications.